Skip to content

Latest commit

 

History

History
254 lines (178 loc) · 12.2 KB

File metadata and controls

254 lines (178 loc) · 12.2 KB

GitHub AI Scan License

This GitHub AI Scan License (the "License") governs the limited right to download and execute the AI Scan as part of GitHub's AI Scan feature. It is between GitHub ("GitHub") and the customer receiving Authorized Access ("Customer"). The License is effective as of the earliest of the Customer's acceptance of the applicable Agreement, receipt of a Preview invitation, or first use of the Runtime (the "Effective Date").

  1. DEFINITIONS

    1. Definitions. In this License:

      1. "Agreement" means the applicable written agreement between GitHub and the Customer governing the Customer's use of GitHub products and services, including any Additional Product Terms, Generative AI Services Terms, Data Protection Agreement, and applicable order form.
      2. "AI Scan" means GitHub's managed AI-powered security-scanning feature, however branded.
      3. "AI Scan Runtime" or "Runtime" means the software artifacts, command-line interface, GitHub Action wrapper, and related supporting files distributed by GitHub to enable execution of AI Scan.
      4. "Authorized Access" means access granted to the Customer through (i) a written AI Scan preview invitation, (ii) an active AI Scan subscription or entitlement, (iii) an order form, or (iv) a GHAS or Code Security entitlement that includes AI Scan.
      5. "Authorized Codebase" means a repository or codebase that the Customer owns, controls, develops, maintains, or is otherwise authorized to test.
      6. "Approved Invocation" means initiation of AI Scan through a GitHub-provided user interface, API, or other mechanism expressly approved by GitHub in documentation.
      7. "Approved Runner" means a GitHub-hosted runner or, if and to the extent GitHub expressly permits in documentation, an approved self-hosted runner.
      8. "Customer" means the person or entity receiving Authorized Access under the Agreement.
  2. LICENSE GRANT

    1. Grant. Subject to the Agreement and the License, GitHub grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the period of Authorized Access to:

      1. permit an approved GitHub Actions workflow associated with an Authorized Codebase to download the unmodified Runtime from the GitHub-designated distribution location;
      2. make temporary or cached copies of the Runtime that are technically required to execute the workflow;
      3. execute the unmodified Runtime on an Approved Runner;
      4. invoke the Runtime only through an Approved Invocation;
      5. use the Runtime only to scan Authorized Codebases; and
      6. receive and use security findings generated by AI Scan for the Customer's internal security purposes.
    2. Automated Copying and Execution. The license in Section 2.1 expressly permits the automated download, caching, and execution of the Runtime that occurs when a GitHub Actions workflow runs AI Scan on an Approved Runner.
    3. License Conditions. The license is conditioned on and continues only while the Customer maintains:

      1. a valid Agreement;
      2. Authorized Access;
      3. applicable enterprise, organization, and repository enablement of AI Scan;
      4. payment of applicable AI consumption charges;
      5. compliance with the Customer's model policies and GitHub's approved-model list; and
      6. compliance with GitHub's Acceptable Use Policies and applicable law.
    4. No Source or Internal Materials. Except for rights independently granted under an applicable third-party license, no rights are granted under this License to GitHub’s proprietary source code, system prompts, scanning logic, build instructions, tests, evaluation materials, model weights, query logic, or other internal materials.
  3. RESTRICTIONS

    1. Restrictions. Except to the extent required by mandatory law or by an applicable third-party license, Customer must not, and must not allow any third party to:

      1. directly invoke or operate the Runtime outside an Approved Invocation;
      2. modify, adapt, translate, or create derivative works from the Runtime;
      3. reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, prompts, or internal operation of the Runtime;
      4. redistribute, publish, transfer, lend, or sublicense the Runtime;
      5. sell, lease, or commercially exploit the Runtime;
      6. offer the Runtime as a standalone or integrated product or hosted scanning service;
      7. use the Runtime to provide scanning services to third parties;
      8. bypass authentication, entitlement checks, model policies, consumption meters, technical restrictions, or usage limits;
      9. remove or alter copyright, trademark, attribution, or proprietary notices;
      10. scan a repository or codebase that Customer is not authorized to test;
      11. use the Runtime in violation of law, applicable sanctions, export controls, or the Agreement; or
      12. use a copied or cached Runtime after Authorized Access ends, except as necessary for ordinary automated technical cleanup.
    2. Mandatory-Law Exception. The restrictions in Section 3.1(c) do not apply to the extent applicable law grants Customer non-waivable rights to reverse engineer for interoperability or similar purposes.
  4. PUBLIC REPOSITORY; UNAUTHORIZED DOWNLOADS

    1. Distribution Mechanism Only. GitHub may host the Runtime in a publicly accessible repository solely so that GitHub Actions workflows can download and execute it. Public accessibility is a distribution mechanism only.
    2. No Open Source; No Implied Grant. Public availability of the Runtime:

      1. does not make GitHub’s proprietary portions of the Runtime open-source software;
      2. does not grant any person access to AI Scan or GitHub's AI services;
      3. does not grant any license under GitHub’s proprietary rights to any person who does not have Authorized Access;
      4. does not create any entitlement based on mere possession of a copy; and
      5. does not limit GitHub's right to authenticate, authorize, meter, throttle, disable, or reject use of the Runtime or the AI service.
    3. Access Controls. Access to AI Scan services remains subject to authentication, product entitlement, customer model policy, and consumption controls. GitHub may technically block or reject unauthorized use.
  5. THIRD-PARTY SOFTWARE

    1. Third-Party Components. The Runtime may include third-party software and materials governed by separate license terms. Applicable license texts, copyright notices, attribution notices, and other required notices are identified in the `THIRD-PARTY-LICENSES.md` file distributed with the Runtime.
    2. Separate Terms. To the extent required by an applicable third-party license, that license governs the applicable third-party component. Nothing in this License limits rights granted directly under an applicable open-source or third-party license.
  6. AI SERVICES AND CUSTOMER DATA

    1. AI Services. The Runtime invokes GitHub-hosted AI and related services. This License does not independently grant access to those services. Use of the services is governed by the Agreement and the applicable product, generative-AI, privacy, and data-protection terms.
    2. Models and Findings. Model availability is subject to GitHub support and Customer model policies. Security findings may be AI-generated. Product documentation describes relevant processing, retention, and controls.
  7. SEPARATELY LICENSED GITHUB PRODUCTS; CODEQL

    1. Separately Licensed Products. GitHub products, services, or components that are separately licensed remain subject to their own terms. This License does not grant rights to any such product, service, or component.
  8. OWNERSHIP

    1. Ownership. GitHub and its licensors retain all right, title, and interest in and to the Runtime. The Runtime is licensed, not sold.
    2. No Implied Licenses. No licenses are granted by implication, estoppel, or otherwise. GitHub reserves all rights not expressly granted. No source-code rights and no trademark or branding rights are granted.
    3. Customer Content. Customer retains its rights in its code and other content, subject to the Agreement.
  9. UPDATES AND TECHNICAL OPERATION

    1. Updates. GitHub may issue automatic or required Runtime updates, and may replace, deprecate, or discontinue Runtime versions.
    2. Integrity. GitHub may use checksums, signatures, or other integrity controls. Customer must not circumvent them.
    3. Caching and Cleanup. GitHub Actions may temporarily cache the Runtime. GitHub may remove or invalidate obsolete versions. Direct local use of the Runtime is not supported.
    4. No Compatibility Promise. GitHub does not promise backward compatibility, a fixed model, continued availability of any version, or any specific feature except as required by the Agreement.
  10. TERM AND TERMINATION

    1. Term. This License is effective on the Effective Date and continues only while the Customer has Authorized Access.
    2. Termination. This License terminates automatically when Authorized Access ends and may be terminated by GitHub for breach or as permitted by the Agreement.
    3. Effect of Termination. On termination or expiration:

      1. Customer must stop using the Runtime;
      2. all rights granted under this License end, without affecting rights independently granted under an applicable third-party license;
      3. Customer must delete copies of the Runtime under its control, subject to ordinary automated backup and cache-cleanup processes;
      4. GitHub may disable access to the AI service; and
      5. accrued payment obligations and Sections 3, 4, 5, 7, 8, 10.3, 11, and 12 survive.
    4. Public Availability After Termination. The Runtime may remain technically downloadable from the public repository after termination. Continued public availability does not extend or revive any license.
  11. WARRANTIES, LIABILITY, AND AGREEMENT HIERARCHY

    1. Agreement Controls. Warranty disclaimers, liability limitations, indemnities, governing-law, dispute-resolution, export, and trade-compliance obligations are governed by the Agreement and incorporated by reference. Support and service levels are governed by the Agreement and applicable product documentation.
    2. AI Output Disclaimer. AI Scan findings may be inaccurate, incomplete, or fail to identify vulnerabilities. AI Scan supplements and does not replace Customer's own security testing, secure-development practices, and code review.
    3. Mandatory Law. Nothing in this License limits rights or remedies that cannot be limited under applicable mandatory law.
    4. Fallback Standalone Terms. If no Agreement supplies governing law, this License is governed by the laws of the State of California, excluding conflicts-of-law rules, with exclusive venue in the state and federal courts located in San Francisco County, California.
  12. ACCEPTANCE AND INCORPORATION

    1. Acceptance. This License is accepted by the earliest of:

      1. the Customer's execution or acceptance of an Agreement that incorporates this License by reference;
      2. the Customer's acceptance of a preview invitation that incorporates this License; or
      3. the Customer's download, installation, or execution of the Runtime.
  13. GENERAL

    1. Notices. Notices are given as provided in the Agreement.
    2. Assignment. Customer must not assign License except as permitted by the Agreement. GitHub may assign to an affiliate or successor.
    3. Entire Agreement; Amendments. Together with the Agreement and referenced documents, this License is the entire agreement regarding the Runtime. Amendments are governed by the Agreement.
    4. Severability. If a provision is unenforceable, the remainder remains in effect.
    5. Counterparts; Electronic Signatures. This License may be accepted electronically and in counterparts.